Rights of Data Principals
14. (1) For enabling Data Principals to exercise their rights under the Act, the Data Fiduciary and, where applicable, the Consent Manager, shall prominently publish on its website or app, or both, as the case may be, ΓÇö
(a) the details of the means using which a Data Principal may make a request for the exercise of such rights; and
(b) the particulars, if any, such as the username or other identifier of such a Data Principal, which may be required to identify her under its terms of service.
(3) Every Data Fiduciary and Consent Manager shall prominently publish... a reasonable period not exceeding ninety days under its grievance redressal system for responding to the grievances of Data Principals...
What this means: Companies cannot make it difficult for you to exercise your rights (like asking them to delete your data). They must clearly publish the exact steps you need to take on their website.
Also, if you file a privacy grievance with a company, they are legally required to resolve it within a maximum of 90 days.
Key Practical Takeaways for Compliance Teams
-
•
Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
-
•
Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 14.
-
•
Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.